ruleset-sources: Remove the abuse.ch SSL list from the suricata sources
Commit Message
- The abuse.ch ssl suricata list has stopped being updated since 2025-06-25
- Looking at all of the abuse.ch lists, none of them are being updated anymore so abuse.ch
becoming part of spamhaus looks to have stopped all work on free versions of the lists
- This change modifies the abuse.ch entry so that it no longer can be installed but also
if already installed it will remove it.
- The patch has also made a few minor typo corrections in comments.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/suricata/ruleset-sources | 9 +++------
1 file changed, 3 insertions(+), 6 deletions(-)
@@ -27,7 +27,7 @@ our %Providers = (
dl_type => "archive",
},
- # Ruleset for registered sourcefire users with a valid subsription.
+ # Ruleset for registered sourcefire users with a valid subscription.
subscripted => {
summary => "Talos VRT rules with subscription",
website => "https://www.snort.org",
@@ -47,7 +47,7 @@ our %Providers = (
dl_type => "archive",
},
- # Emerging threads community rules.
+ # Emerging threats community rules.
emerging => {
summary => "Emergingthreats.net Community Rules",
website => "https://emergingthreats.net/",
@@ -57,7 +57,7 @@ our %Providers = (
dl_type => "archive",
},
- # Emerging threads Pro rules.
+ # Emerging threats Pro rules.
emerging_pro => {
summary => "Emergingthreats.net Pro Rules",
website => "https://emergingthreats.net/",
@@ -72,9 +72,6 @@ our %Providers = (
summary => "Abuse.ch SSLBL Blacklist Rules",
website => "https://sslbl.abuse.ch/",
tr_string => "sslbl blacklist rules",
- requires_subscription => "False",
- dl_url => "https://sslbl.abuse.ch/blacklist/sslblacklist.rules",
- dl_type => "plain",
},
# Etnetera Aggressive Blacklist.